From 496cf642aad37d5f15ae1324979e63b6068ccb070323a060cc1c5579111fd2bd Mon Sep 17 00:00:00 2001 From: OBS User buildservice-autocommit Date: Wed, 10 Nov 2010 17:09:52 +0000 Subject: [PATCH 1/2] Updating link to change in openSUSE:Factory/dbus-1 revision 58.0 OBS-URL: https://build.opensuse.org/package/show/Base:System/dbus-1?expand=0&rev=78f34a9f0d489bc1a76e6dd32289475c --- dbus-1-x11.changes | 5 +++++ dbus-1-x11.spec | 7 ++++--- dbus-1.spec | 2 +- 3 files changed, 10 insertions(+), 4 deletions(-) diff --git a/dbus-1-x11.changes b/dbus-1-x11.changes index 4da385a..a8e6855 100644 --- a/dbus-1-x11.changes +++ b/dbus-1-x11.changes @@ -1,3 +1,8 @@ +------------------------------------------------------------------- +Mon Nov 8 14:52:11 UTC 2010 - aj@suse.de + +- Fix package list, own /lib/systemd directories. + ------------------------------------------------------------------- Tue Oct 12 14:35:53 UTC 2010 - cristian.rodriguez@opensuse.org diff --git a/dbus-1-x11.spec b/dbus-1-x11.spec index 2ae2372..2eac2ab 100644 --- a/dbus-1-x11.spec +++ b/dbus-1-x11.spec @@ -1,7 +1,7 @@ # -# spec file for package dbus-1-x11 (Version 1.2.16) +# spec file for package dbus-1-x11 (Version 1.4.0) # -# Copyright (c) 2009 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2010 SUSE LINUX Products GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -17,6 +17,7 @@ # norootforbuild + Name: dbus-1-x11 BuildRequires: xorg-x11-devel Url: http://dbus.freedesktop.org/ @@ -28,7 +29,7 @@ Summary: D-Bus Message Bus System BuildRequires: doxygen libexpat-devel libzio pkgconfig BuildRequires: audit-devel Version: 1.4.0 -Release: 3 +Release: 4 AutoReqProv: on # bug437293 %ifarch ppc64 diff --git a/dbus-1.spec b/dbus-1.spec index c72aa09..f8887b1 100644 --- a/dbus-1.spec +++ b/dbus-1.spec @@ -27,7 +27,7 @@ Summary: D-Bus Message Bus System BuildRequires: doxygen libexpat-devel libzio pkgconfig BuildRequires: audit-devel Version: 1.4.0 -Release: 3 +Release: 4 AutoReqProv: on # bug437293 %ifarch ppc64 From d1a60108a2aa4dd925857f332053dd5f6c6490e3e67fca852659ecfe8625fc39 Mon Sep 17 00:00:00 2001 From: Dirk Mueller Date: Mon, 3 Jan 2011 09:48:19 +0000 Subject: [PATCH 2/2] Accepting request 56988 from home:javierllorente:branches:Base:System OBS-URL: https://build.opensuse.org/request/show/56988 OBS-URL: https://build.opensuse.org/package/show/Base:System/dbus-1?expand=0&rev=34 --- dbus-1-x11.changes | 13 +++++++++++++ dbus-1-x11.spec | 7 +++---- dbus-1-x11.spec.in | 4 ++-- dbus-1.4.0.tar.bz2 | 3 --- dbus-1.4.1.tar.bz2 | 3 +++ dbus-1.changes | 13 +++++++++++++ dbus-1.spec | 6 +++--- 7 files changed, 37 insertions(+), 12 deletions(-) delete mode 100644 dbus-1.4.0.tar.bz2 create mode 100644 dbus-1.4.1.tar.bz2 diff --git a/dbus-1-x11.changes b/dbus-1-x11.changes index a8e6855..f007483 100644 --- a/dbus-1-x11.changes +++ b/dbus-1-x11.changes @@ -1,3 +1,16 @@ +------------------------------------------------------------------- +Sun Jan 2 12:54:14 UTC 2011 - javier@opensuse.org + +- Update to 1.4.1 + + Fix for CVE-2010-4352: sending messages with excessively-nested + variants can crash the bus. The existing restriction to 64-levels + of nesting previously only applied to the static type signature; + now it also applies to dynamic nesting using variants. Thanks to + Rémi Denis-Courmont for discoving this issue. + + Various bug fixes. + + For details, see + http://lists.freedesktop.org/archives/dbus/2010-December/013861.html + ------------------------------------------------------------------- Mon Nov 8 14:52:11 UTC 2010 - aj@suse.de diff --git a/dbus-1-x11.spec b/dbus-1-x11.spec index 2eac2ab..16a287e 100644 --- a/dbus-1-x11.spec +++ b/dbus-1-x11.spec @@ -1,7 +1,7 @@ # -# spec file for package dbus-1-x11 (Version 1.4.0) +# spec file for package dbus-1-x11 (Version 1.4.1) # -# Copyright (c) 2010 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2011 SUSE LINUX Products GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -17,7 +17,6 @@ # norootforbuild - Name: dbus-1-x11 BuildRequires: xorg-x11-devel Url: http://dbus.freedesktop.org/ @@ -28,7 +27,7 @@ Summary: D-Bus Message Bus System # COMMON1-BEGIN BuildRequires: doxygen libexpat-devel libzio pkgconfig BuildRequires: audit-devel -Version: 1.4.0 +Version: 1.4.1 Release: 4 AutoReqProv: on # bug437293 diff --git a/dbus-1-x11.spec.in b/dbus-1-x11.spec.in index 21a7fd8..c90a0ab 100644 --- a/dbus-1-x11.spec.in +++ b/dbus-1-x11.spec.in @@ -1,7 +1,7 @@ # -# spec file for package dbus-1-x11 (Version 1.2.16) +# spec file for package dbus-1-x11 (Version 1.4.1) # -# Copyright (c) 2009 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2011 SUSE LINUX Products GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed diff --git a/dbus-1.4.0.tar.bz2 b/dbus-1.4.0.tar.bz2 deleted file mode 100644 index 78e41b8..0000000 --- a/dbus-1.4.0.tar.bz2 +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:27db28e3bd270e482c794e35c2a474c92383bfb4a7f3467a1cacd6ffe77f1988 -size 1459728 diff --git a/dbus-1.4.1.tar.bz2 b/dbus-1.4.1.tar.bz2 new file mode 100644 index 0000000..298ffd3 --- /dev/null +++ b/dbus-1.4.1.tar.bz2 @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:957973032701c9a6625117f793513a0d8b1cd6a6bf35b5d775c762c05f1a4aec +size 1443101 diff --git a/dbus-1.changes b/dbus-1.changes index a8e6855..f007483 100644 --- a/dbus-1.changes +++ b/dbus-1.changes @@ -1,3 +1,16 @@ +------------------------------------------------------------------- +Sun Jan 2 12:54:14 UTC 2011 - javier@opensuse.org + +- Update to 1.4.1 + + Fix for CVE-2010-4352: sending messages with excessively-nested + variants can crash the bus. The existing restriction to 64-levels + of nesting previously only applied to the static type signature; + now it also applies to dynamic nesting using variants. Thanks to + Rémi Denis-Courmont for discoving this issue. + + Various bug fixes. + + For details, see + http://lists.freedesktop.org/archives/dbus/2010-December/013861.html + ------------------------------------------------------------------- Mon Nov 8 14:52:11 UTC 2010 - aj@suse.de diff --git a/dbus-1.spec b/dbus-1.spec index f8887b1..e5b61fa 100644 --- a/dbus-1.spec +++ b/dbus-1.spec @@ -1,7 +1,7 @@ # -# spec file for package dbus-1 (Version 1.4.0) +# spec file for package dbus-1 (Version 1.4.1) # -# Copyright (c) 2010 SUSE LINUX Products GmbH, Nuernberg, Germany. +# Copyright (c) 2011 SUSE LINUX Products GmbH, Nuernberg, Germany. # # All modifications and additions to the file contributed by third parties # remain the property of their copyright owners, unless otherwise agreed @@ -26,7 +26,7 @@ Summary: D-Bus Message Bus System # COMMON1-BEGIN BuildRequires: doxygen libexpat-devel libzio pkgconfig BuildRequires: audit-devel -Version: 1.4.0 +Version: 1.4.1 Release: 4 AutoReqProv: on # bug437293